Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.11K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
MICROSOFT SECURITY BULLETIN COVERAGE FOR MAY 2024

Overview Microsoft’s May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of

https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/


πŸŽ–@malwr
Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft

https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/


πŸŽ–@malwr
Tracking the Progression of Earth Hundun's Cyberespionage Campaign in 2024

This report describes how Waterbear and Deuterbear β€” two of the tools in Earth Hundun's arsenal β€” operate, based on a campaign from 2024.

https://www.trendmicro.com/en_us/research/24/e/earth-hundun-2.html


πŸŽ–@malwr
πŸ‘1
To the Moon and back(doors): Lunar landing in diplomatic missions

ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs

https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/


πŸŽ–@malwr
Talos releases new macOS open-source fuzzer

Compared to fuzzing for software vulnerabilities on Linux, where most of the code is open-source, targeting anything on macOS presents a few difficulties.

https://blog.talosintelligence.com/talos-releases-new-macos-fuzzer/


πŸŽ–@malwr
Hackers use Malicious OneNote files for Delivering Payloads to Victims

Microsoft OneNote is a digital note-taking app in the Microsoft Office Suite. Hackers use it to embed malicious objects like scripts and executables, tricking users into downloading malware. The malware aims to deliver malicious payloads like Qakbot, Emotet, and AsyncRAT. Attackers prefer lightweight malware for easier delivery, avoiding heavier files like EXE or Office 97-2003 files.

https://hackhunting.com/2024/05/17/hackers-use-malicious-onenote-files-for-delivering-payloads-to-victims/


πŸŽ–@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
❀5
Exploit PoC released for Zabbix Server SQL injection vulnerability – CVE-2024-22120

A critical time-based SQL injection vulnerability (CVE-2024-22120, severity 9.1) affects Zabbix Server versions 6.0.0 - 6.0.27, 6.0.28rc1, 6.4.0 - 6.4.12, 6.4.13rc1, 7.0.0alpha1 - 7.0.0beta1, and 7.0.0beta2. Exploitation allows privilege escalation to admin and potential remote code execution. A $3000 exploit code has been shared on GitHub. Users are advised to update.

https://hackhunting.com/2024/05/21/exploit-poc-released-for-zabbix-server-sql-injection-vulnerability-cve-2024-22120/


πŸŽ–@malwr
πŸ‘4
Politically Charged Ransomware Weaponized as a File Destroyer

The SonicWall Capture Labs threat research team has been observing a growth of malware built using the Chaos ransomware builder. The sample we have analyzed here is built using this kit, however, it is not

https://blog.sonicwall.com/en-us/2024/05/politically-charged-ransomware-weaponized-as-a-file-destroyer/


πŸŽ–@malwr
From trust to trickery: Brand impersonation over the email attack vector

Cisco recently developed and released a new feature to detect brand impersonation in emails when adversaries pretend to be a legitimate corporation.

https://blog.talosintelligence.com/from-trust-to-trickery-brand-impersonation/


πŸŽ–@malwr